Oracle Database 10g uses a NULL pDacl parameter when calling the SetSecurityDescriptorDacl function to create discretionary access control lists (DACLs), which allows local users to gain privileges.
| Software | From | Fixed in |
|---|---|---|
| oracle / database_server | 10.2.2 | 10.2.2.x |
| oracle / database_server | 10.2.3 | 10.2.3.x |
| oracle / database_server | 10.2.1 | 10.2.1.x |